London-based fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.
The exposed data included customers' identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver's licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories.
A Revolut spokesperson said the company identified a "sophisticated external impersonation scam" where an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. The firm blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and regulators.
Revolut did not disclose the exact number of impacted individuals, which government agency was involved, or whether the incident was limited to a specific market. The spokesperson said only that a "limited" number of customers were impacted.
Well-known crypto security researcher ZachXBT posted about Revolut's notification email late on Friday, suggesting the incident appeared to have been targeted at high net worth users.
The breach comes as Revolut, which has more than 80 million customers globally and operates as a bank in more than 30 countries, reportedly weighs a potential public listing. Earlier this month the U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.